CMMC CONSULTANT BUYING BRIEF Company: [name] Date: [date] Please send a scoped proposal for the work below. Keep advice, hands-on technical work, ongoing services, and any formal assessment on separate lines. 1. REQUIREMENT AND GOAL Required CMMC level and assessment type: [e.g., Level 2 (Self) / unknown] Where the requirement comes from: [clause or subcontract section, no sensitive details / unknown] What we want from this work: [confirm our scope / review our evidence / fix our SSP / plan fixes / make agreed technical changes / other] Deadline: [date and non-sensitive reason / none known] Tell us what you need to confirm before you can price the work. Do not fill in anything we marked unknown with an assumption. 2. OUR SETUP (HIGH LEVEL ONLY) Information we handle: [FCI / CUI / both / unknown] People and locations that touch it: [rough numbers] IT environment: [e.g., Microsoft 365 commercial or GCC High, on-site servers, mix / unknown] Who runs IT today: [internal staff / MSP / both / unknown] Existing documents: [SSP yes / no / unknown; last updated if known] SPRS record: [NIST Basic / CMMC Level 1 / CMMC Level 2 / unknown] Assessment date and current affirmation: [known details / unknown] 3. WORK AND DELIVERABLES For each piece of work, tell us: - The deliverable and its format (editable files we keep) - What "done" looks like and how we can check it - What you need from us, and who approves the result - Whether you will advise, implement, test, or maintain it 4. PEOPLE Name the people who will do the work, their CMMC credentials (RP, RPA, CCP, CCA), and where we can verify them. Tell us how you handle staff substitutions. 5. INDEPENDENCE Disclose whether you or an affiliate is a C3PAO, employs assessors, or has provided us consulting, implementation, or product sales/services. Identify who would conduct any Level 2 certification assessment and document the applicable three-year restrictions and other conflicts. Do not propose an assessing C3PAO or assessment-team member barred by those rules. Describe any customer-side assessment support separately. List products you resell (cloud, software, enclave) that you may recommend. 6. PRICE AND EXCLUSIONS Separate one-time fees, recurring fees, and the hours you expect from our staff. List rates for extra work, licenses, third-party costs, travel, and any assumption that could change the price. Do not bundle a formal assessment fee into this proposal. 7. RECORDS AND EXIT Confirm we own, or have full use of, every deliverable in editable form, and can export our records if we end the engagement. We must keep our Level 2 assessment evidence for six years from the CMMC Status Date. For other records, identify the retention requirement that applies. Explain how you will receive and protect sensitive information once we approve a secure channel. 8. PROMISES Confirm that you do not guarantee any assessment result. Do not send CUI, drawings, passwords, network diagrams, or sensitive contract details with this brief. Share them only through a secure channel after you choose a provider.